Atlas / MCP servers / joungminsung / OpenDocuments

OpenDocumentsBLOCK

mcp/joungminsung/opendocuments

Self-hosted RAG platform for AI document search across GitHub, Notion, Google Drive, local files, and web sources with citations.

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
20 13r · 5w · 2d
Transport
stdio
License
MIT
Stars
115
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

OpenDocuments Self-hosted RAG platform for AI document search across GitHub, Notion, Google Drive, Confluence, S3, local files, and web sources

English | 한국어

What is OpenDocuments?

OpenDocuments is an open source, self-hosted RAG (Retrieval-Augmented Generation) platform that turns scattered company documents into an AI-searchable knowledge base. It connects to sources like GitHub, Notion, Google Drive, Confluence, S3, Swagger/OpenAPI, local files, and web pages, indexes them with hybrid vector + keyword search, and answers natural-language questions with cited sources.

Use OpenDocuments when you want:

  • A self-hosted alternative to enterprise AI search and proprietary knowledge-base search tools
  • AI document search with citations f
Read from source at commit c8a151c2afedOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add opendocuments-parser-xlsx --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env AWS_ACCESS_KEY_ID=${AWS_ACCESS_KEY_ID} --env AWS_SECRET_ACCESS_KEY=${AWS_SECRET_ACCESS_KEY} --env AWS_SESSION_TOKEN=${AWS_SESSION_TOKEN} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "opendocuments-parser-xlsx": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
        "AWS_ACCESS_KEY_ID": "${AWS_ACCESS_KEY_ID}",
        "AWS_SECRET_ACCESS_KEY": "${AWS_SECRET_ACCESS_KEY}",
        "AWS_SESSION_TOKEN": "${AWS_SESSION_TOKEN}"
      }
    }
  }
}
03

Exposed tools (20)

13 read · 5 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
PoliciesreadOperational policies
opendocuments_askreadQuery the RAG engine with a natural language question and get an answer with sources
opendocuments_config_getreadGet configuration value
opendocuments_config_setwriteSet a config value (note: edit opendocuments.config.ts directly)
opendocuments_connector_listwriteList registered connectors and their sync status
opendocuments_connector_syncwriteSync a connector to discover and index new documents
opendocuments_doctorwriteRun a health check on the OpenDocuments system and report status of all components
opendocuments_document_deletedestructiveDelete a document (soft)
opendocuments_document_getreadGet document details by ID
opendocuments_document_listreadList all indexed documents in the document store
opendocuments_document_reindexreadReindex a document
opendocuments_index_pathreadIndex a local file or directory into the document store
opendocuments_index_statusreadGet indexing status
opendocuments_plugin_addwriteInstall a plugin
opendocuments_plugin_listreadList installed plugins
opendocuments_plugin_removedestructiveRemove a plugin
opendocuments_searchreadPerform a vector similarity search without LLM generation, returning raw document chunks
opendocuments_statsreadGet system statistics including document count, workspace count, and plugin info
opendocuments_workspace_listreadList workspaces
opendocuments_workspace_switchreadSwitch workspace
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (4 observation(s))
Network
declared (8 observation(s))
Shell
declared (6 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (18)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
packages/core/src/storage/db.ts:10
exec(sql: string): void
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
packages/core/src/storage/sqlite.ts:20
exec(sql: string): void {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
packages/server/src/http/app.ts:40
if (origin.startsWith('http://localhost:') || origin.startsWith('http://127.0.0.1:')) {
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
opendocuments_document_delete, opendocuments_plugin_remove
Why it matters. 2 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/cli/src/commands/start.ts:18
const packagedPath = resolve(thisDir, '../../web-dist')
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/cli/src/commands/start.ts:21
const relativePath = resolve(thisDir, '../../../web/dist')
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/cli/tests/commands/backup.test.ts:5
import { createBackup, restoreBackup } from '../../src/commands/backup.js'
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/cli/tests/commands/reset-index.test.ts:6
import { prepareIndexReset } from '../../src/commands/reset-index.js'
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/core/tests/_fixtures/mock-models.ts:2
import type { ModelPlugin } from '../../src/plugin/interfaces.js'
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs-site/guide/deployment.md:84
proxy_pass http://127.0.0.1:3000;
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
docs-site/package.json
vitepress
Why it matters. 1 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@changesets/cli, turbo, typescript
Why it matters. 3 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/cli/package.json
@hono/node-server, @inquirer/prompts, @opendocuments/connector-confluence, @opendocuments/connector-gdrive, @opendocuments/connector-github, @opendocuments/connector-notion, @opendocuments/connector-s
Why it matters. 30 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/client/package.json
typescript, vitest
Why it matters. 2 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/core/package.json
@lancedb/lancedb, better-sqlite3, chalk, eventemitter3, jiti, js-tiktoken, semver, zod
Why it matters. 12 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docker/demo/docs/06-github-connector.md:22
1. The admin UI sends repository, branch, token, path filters, and sync interval to the server.
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docker/demo/docs/04-security-and-operations.md:5
- API keys and secrets are read from environment variables, not hardcoded.
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/superpowers/plans/2026-06-25-platform-hardening-and-web-workbench.md:21
- [ ] Add failing tests that verify read-only team API keys cannot upload, delete, restore, or share conversations.
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha c8a151c2afedfull audit observations/trust-audit/mcp-server/joungminsung__opendocuments.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07c8a151c2afedBLOCKD69first audit
06

Questions

What is the OpenDocuments MCP server?

Self-hosted RAG platform for AI document search across GitHub, Notion, Google Drive, local files, and web sources with citations.

What tools does OpenDocuments expose?

20 in total: 13 read-only, 5 that write, and 2 that can delete or overwrite (opendocuments_document_delete, opendocuments_plugin_remove). Every one is listed on this page with its risk.

Is OpenDocuments safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does OpenDocuments need?

It reads ANTHROPIC_API_KEY, AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_SESSION_TOKEN, CONFLUENCE_TOKEN, GDRIVE_ACCESS_TOKEN, GITHUB_TOKEN, GOOGLE_ACCESS_TOKEN, GOOGLE_API_KEY, NOTION_TOKEN, OPENAI_API_KEY and OPENDOCUMENTS_MODEL_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does OpenDocuments run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as opendocuments-parser-xlsx at 0.1.1.

How current is this page?

The grade is for one exact copy of the source (c8a151c2afed), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement